Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer is designing a centralized logging solution for a multi-account AWS environment using AWS Organizations. The solution must ensure that all CloudTrail logs from all accounts are delivered to a single S3 bucket in the security account. Additionally, the logs must be encrypted with a KMS key that is managed by the security account. Which combination of steps is required?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a trail in each account, each delivering to the same S3 bucket. Use a bucket policy to allow cross-account writes. Use a single KMS key with appropriate key policy.

It uses individual trails in each account, all configured to deliver to the same centralized S3 bucket in the security account. A bucket policy can grant CloudTrail write permissions from all accounts, and a single KMS key (managed by the security account) with appropriate key policy ensures encryption. This approach meets the centralized logging and encryption requirements without violating organization trail constraints. Option B is incorrect because AWS Config does not deliver CloudTrail logs, and CloudWatch Logs streaming is not the required solution. Option C is incorrect because the trail is created in the management account but delivers to a bucket in the management account, not the security account, and it uses default encryption instead of a customer-managed KMS key from the security account. Option D is incorrect because organization trails can only be created in the management account; creating one in the security account is not allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a trail in each account, each delivering to the same S3 bucket. Use a bucket policy to allow cross-account writes. Use a single KMS key with appropriate key policy.

    Why this is correct

    Correct. Each account's trail sends logs to the central S3 bucket in the security account. The bucket policy allows cross-account writes, and the KMS key policy grants necessary permissions for CloudTrail and S3 from all accounts.

  • ✗

    Use AWS Config to deliver logs to a central bucket. Enable CloudWatch Logs in each account and stream to the security account.

    Why it's wrong here

    AWS Config does not ingest or forward CloudTrail audit logs; it records resource configuration history and compliance states, delivering its own snapshots to S3, which is unrelated to CloudTrail's JSON log files. While you can configure a trail to send CloudTrail events to CloudWatch Logs in the same account, the description here omits the required trail and instead proposes CloudWatch Logs streaming, which would require additional subscription filters or cross-account destinations and still does not centralize the raw CloudTrail logs into a security account S3 bucket.

  • ✗

    Create a trail in the management account with organization trail enabled, delivering to a bucket in the management account. Use KMS default encryption.

    Why it's wrong here

    Creating an organization trail in the management account is valid, but delivering to a bucket in the management account defeats the purpose of centralized logging in the security account: the security account would have no direct access to the logs unless a separate cross-account replication or access mechanism is built. Moreover, using S3 default encryption (SSE-S3) instead of a customer-managed KMS key in the security account means the security account cannot centrally control or audit key usage, and CloudTrail cannot write logs encrypted with a key that the security account manages. The requirement calls for a single KMS key with a key policy that grants CloudTrail and S3 permissions from all accounts, which is not satisfied by SSE-S3.

  • ✗

    Create a trail in the security account with organization trail enabled, delivering to a bucket in the security account. Configure bucket policy and KMS key policy to allow CloudTrail and S3 from all accounts.

    Why it's wrong here

    An organization trail that collects events from all member accounts can only be created and managed by the management account (or a designated delegate) — the security account is not the management account in this design, so it cannot create an organization trail. Even if the security account were the management account, the bucket and KMS key policies would need to explicitly identify CloudTrail as a service principal and all member account IDs as principals, but the core failure is that the proposed trail creation origin is invalid.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.